CVE-2026-82549
Received Received - Intake

Improper Integrity Check Validation in Linux Foundation Magma 1.9.0

Vulnerability report for CVE-2026-82549, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_foundation magma 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Linux Foundation Magma 1.9.0, specifically in the SecurityModeComplete Handler component. It allows improper validation of integrity check values, enabling remote attacks. An exploit is publicly available.

Detection Guidance

To detect this vulnerability, monitor for UE devices declaring the IA0 integrity algorithm during the SecurityModeComplete process. Check AMF logs for registration attempts with MAC value of 0. Inspect NAS packets for crafted messages during initial registration. Use network traffic analyzers like Wireshark to capture and analyze 3GPP signaling messages for anomalies.

Impact Analysis

This flaw lets attackers bypass integrity protection by manipulating the SecurityModeComplete process. It could enable replay attacks where valid messages are intercepted and retransmitted without detection, weakening overall security.

Compliance Impact

This vulnerability allows bypassing integrity protection in the Magma Access Gateway, which could lead to unauthorized interception or manipulation of sensitive data. For GDPR, this may violate requirements for data integrity and confidentiality. For HIPAA, it could compromise protected health information integrity during transmission.

Mitigation Strategies

Apply the latest Magma software patches from the Linux Foundation repository. Update AMF configurations to reject UE declarations of IA0 integrity algorithm. Implement stricter integrity protection enforcement in the SecurityModeComplete handler. Monitor network traffic for suspicious registration patterns and block unauthorized devices attempting to bypass security checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82549. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart